Known limitations, problems, and workarounds

Known limitations, problems, and workarounds for the IBM Verify Identity Governance - Virtual Appliance

Known issues in IVIG - VA v11.0.0.1

Issues in data sync and ACIs
After installing the IVIG - Virtual Appliance v11.0.0. Fix Pack 1 release, you may notice errors in data sync or issues in modifying Access Control Items (ACIs). To avoid this issue, you must run the ACI Fix utility after the IVIG - Virtual Appliance v11.0.0. Fix Pack 1 installation.
Solution: To avoid this issue, you must run the ACI Fix utility after you complete the IVIG - Virtual Appliance v11.0.0 Fix Pack 1 deployment. Perform the following steps:
  1. Log in to IBM Fix Central.
  2. Search for 11.0.0.0-ISS-IVIG-VA-FP0001 release artifacts.
  3. Download the IVIG11-FP1-aci-fix package.
  4. Extract the contents of package on a Microsoft Windows or Linux computer.
  5. Refer the utility readme file to configure and run the utility.
Remote Syslog Forwarding
IVIG VA v11 FP1 release supports a limited set of log files for forwarding to remote server. The following logs are supported: System, LMI Trace, LMI Messages, Identity Appliance System, Identity Appliance Debug and SDI logs.
The Remote Syslog Forwarder configuration shows some irrelevant log files. The following log files are not relevant for IVIG - Virtual Appliance v11 FP1 release. You may ignore these files:
  • IGI Application Server trace
  • IGI Application Server Messages
  • Broker Application Server trace
  • Broker Application Server Messages
  • OpenID Admin Trace
  • OpenID Admin Messages
  • OpenID SC Trace
  • OpenID SC Messages
  • Progres
  • Product Trace
  • ProductLogs
LMI Authentication Configuration panel is available, but is non-functional in IVIG VA v11 FP1 release.
IVIG VA v11 FP1 release supports some features such as create snapshot, delete snapshot, download snapshot, list snapshot. However, applying a snapshot currently does not work in IVIG VA v11 FP1 release.
Uploading response file fails in the Advanced mode configuration if SSL is enabled for the directory server.
Workaround: To avoid this issue, during IVIG VA v11 FP1 installation, you can configure Advanced mode in non-SSL mode for Directory server, and after IVIG VA is up and running, re-configure the Directory server configuration to SSL mode.
Identity Analytics CLIs and the loadEnterpriseKey CLI are executed only on the Primary node only, not on the member nodes.
In IVIG VA v11 FP1 cluster environment, ensure that Identity Analytics CLIs and the loadEnterpriseKey CLI are executed only on Primary node, and not on the member nodes.